Vulnerability Description
Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Configuroweb | Simple Web Inventory System | 1.0 |
Related Weaknesses (CWE)
References
- https://configuroweb.com/sistema-web-de-inventario-simple-en-php-mysql/Product
- https://github.com/ChuckBartowski7/Vulnerability-Research/blob/main/CVE-2025-603ExploitThird Party Advisory
- https://github.com/configuroweb/inventariobasicoProduct
FAQ
What is CVE-2025-60314?
CVE-2025-60314 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authen...
How severe is CVE-2025-60314?
CVE-2025-60314 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60314?
Check the references section above for vendor advisories and patch information. Affected products include: Configuroweb Simple Web Inventory System.